- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Report all real-time searches from the internal audit index

landen99
Motivator
01-27-2021
11:23 AM
Enable alerts and reports on real-time searches seen in the internal audit index.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

landen99
Motivator
01-27-2021
11:24 AM
The following search presents the real-time searches from the audit index:
index=_audit action=search info=granted search=* NOT ("search_id='scheduler" OR "search='|history" OR "user=splunk-system-user" OR "search='typeahead" OR "search='| metadata type=* | search totalCount>0" OR "| metadata type=sourcetypes | search totalCount > 0" ) "search_id='rt_*"
| table _time user host info savedsearch_name search search_id
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
gjanders

SplunkTrust
01-30-2021
09:33 PM
Nice. In alerts for splunk admins https://splunkbase.splunk.com/app/3796/
I have a few searches to look for bad practices or all time searches in dashboards or similar...FYI
